Skip to content

Microsoft 365 for Aged Care Providers

Almost every aged care provider in Australia runs Microsoft 365, and almost every one of them runs a separate clinical system — Leecare, Manad, a Telstra Health platform or something inherited through acquisition. The question that causes the most trouble is not how to configure either one. It is which information belongs in which.

Get that boundary wrong in one direction and clinical information ends up in SharePoint and Teams, outside the system your clinical governance framework describes. Get it wrong the other way and staff work around the clinical system entirely, because the thing they need at 3am is a phone number and a policy document, not a care plan.

This page is about drawing that line deliberately, and then using Microsoft 365 as the information management layer the strengthened Quality Standards require around it.

What the Standards actually ask for

Strengthened Quality Standard Outcome 2.7 requires providers to put in place an information management system — and, separately, a clinical information system under Outcome 5.1. It treats them as related but distinct, which is the clearest signal available that you are expected to have both and to know which is which.

Outcome 2.7 sets out four things you have to do:

  1. put a system in place
  2. use it to record information
  3. help workers use it well, and
  4. monitor how well it is working.

It also contains a requirement that catches providers out — there must be ways to access critical information when digital systems are offline, including recording clinical information on paper during internet or power outages.

This last point is worth sitting with and considering fully.

Any cloud-first information strategy that has no offline path does not satisfy Outcome 2.7, no matter how well configured it is.

 

Drawing the boundary

The workable rule is that the clinical system holds the record of care, and Microsoft 365 holds everything the organisation needs in order to deliver and evidence that care.

Where information belongs, and why
Information Belongs in Reason
Care and services plans, progress notes, assessments Clinical system Clinical information system under Outcome 5.1
Medication administration records Clinical system Safe and quality use of medicines, Outcome 5.3
Quality Indicator data Clinical system Outcome 2.7 states the clinical system should record it where possible
Policies, procedures, forms Microsoft 365 (SharePoint) Must be current, reviewed and accessible to workers
Correspondence with families and external clinicians Microsoft 365 (email, archived) Record of the exchange, not the clinical record itself
Incident notifications, complaint files, investigation material Both, by design Clinical facts in the clinical system; the paper trail in Microsoft 365
Rosters, shift communication, site coordination Microsoft 365 (Teams) Operational, and needed by staff without clinical system access
Worker records, training, screening evidence Microsoft 365 Human resource management, Outcome 2.9
Board and committee reporting Microsoft 365 Governance, and should be access-restricted

The row that generates the most argument is incident and complaint material, and the answer genuinely is both. The clinical detail belongs where clinical detail belongs. The notification to the Commission, the correspondence with the family, the internal escalation and the investigation notes are organisational records. Trying to force all of it into one system is how providers end up with an incomplete record in each.

The 5 Stages of Information Management

Capture: getting information in once

Outcome 2.7 requires stored information to be "accurate and complete". The most common cause of incomplete records is not carelessness — it is duplicate entry. When a staff member has to record the same thing in two places, one of the two will be wrong, and it will be the one nobody is measured on.

The practical fix is to decide, per information type, which system is authoritative, and then remove the second entry point rather than asking people to be diligent about both. Where information genuinely has to exist in both, it should flow rather than be retyped.

Access: the right information at the right time

The Standard's wording is that the system must give workers "access to the right information at the right time", with access "appropriate to their role". Those two requirements pull against each other, and in aged care the tension is sharper than in most industries.

Your workforce includes permanent staff, agency staff, visiting registered health practitioners, allied health professionals, allied health assistants, contractors and volunteers — many of whom need something on their first shift and should lose it the day their engagement ends. Outcome 2.7 explicitly extends access to visiting practitioners and agency workers, so the answer cannot be to grant only permanent staff access.

This is an identity problem before it is a Microsoft 365 problem. Role-based groups that provision and de-provision automatically are the only approach that survives real turnover; manual access lists become inaccurate within weeks. The detail of how that is built sits on securing resident data in Microsoft 365.

The offline requirement belongs in this section too. Every site needs a defined way to reach critical information and record clinical information on paper when systems or power are unavailable — and it needs to have been tested, because an untested offline procedure is a document rather than a control.

Integrate: information from different sources

Outcome 2.7 requires the system to integrate information from different sources "where needed", and names hospitals as an example. Transitions of care are where information loss does the most harm, and they are also where the boundary between systems is crossed most often.

In Microsoft 365 terms this is usually about the transport rather than the record: making sure a discharge summary that arrives by email or secure message reaches the clinical system reliably, is archived as correspondence, and does not sit unopened in a shared mailbox nobody owns. Shared mailboxes without a named owner and a monitored process are one of the most reliable failure points we find.

Protect: security as part of information management

Outcome 2.7 lists managing cyber security risks as a component of the information management system, cross-referencing Outcome 2.4. Section 168 of the Aged Care Act 2024 separately requires personal information to be protected by "security safeguards that it is reasonable in the circumstances to take". Security is therefore not a layer on top of your information management system — it is part of the definition of one.

Where providers want that expressed as something a board or insurer can verify, SMB1001 certification for aged care providers covers how certification maps to these outcomes.

Review: proving the system works

The fourth Key Task in Outcome 2.7 is the one most often missing. Providers are required to regularly review the information management system, look for improvements, and address what they find — reviewing care and service plans, complaints and feedback, incident information, worker performance, and their own policies.

This is an evidence requirement, and it needs an owner and a cadence. Microsoft 365 supplies much of the raw material through audit logs, access reviews and reporting, but the review itself is a governance activity. Where a provider has no internal capacity for it, that is normally the trigger for a vCIO engagement, which provides the cadence and the documentation an auditor is looking for.

Retention and disposal sit alongside review, and both directions carry obligations — keeping records for the period prescribed under section 154, and destroying or de-identifying personal information once there is no longer a purpose for it. Email archiving for aged care providers covers how those two pull against each other.

The underlying platform work — tenant configuration, identity, device management and the security baseline — is covered under Microsoft modern workplace solutions. This page deals with what changes when the tenant holds aged care records.

Aged Care Microsoft 365 challenges we solve

Improving Care Coordination

Improving Care Coordination

The Microsoft 365 modern workplace, tailored specifically for aged care, gives your teams one secure place to communicate, share documents and coordinate care.

Compliance and the New Act

Compliance and the New Act

The new Aged Care Act requires providers to demonstrate continuous compliance, digital reporting through GPMS, and live access to audit evidence - the Microsoft 365 Modern Workplace is your compliance, information management and security engine!

Securing Resident Data

Securing Resident Data

Securing Resident Data is simplified through the Microsoft 365 system. From Multi-factor Authentication and Data Loss Prevention data protection is available and simple.

Microsoft Teams - The Multi-site collaboration star!

Implement Microsoft Teams as a structured, secure communication hub that mirrors how care operates across regions and facilities, so staff always know where to collaborate and find critical information.

Migrating from legacy systems

What moves to Exchange Online, SharePoint, Teams, Entra ID and Intune, what stays in Leecare or Manad, and how a staged rollout keeps clinical tools running while it happens

Frequently asked questions

Can Microsoft 365 replace our clinical system?

No, and it should not be scoped that way!

Outcome 5.1 requires a clinical information system, and Outcome 2.7 treats it as a distinct component within the broader information management system.

Beyond the compliance position, purpose-built clinical platforms handle assessment, care planning, medication management and Quality Indicator reporting in ways a general productivity platform does not.

Microsoft 365 is the layer around the clinical system, not a substitute for it.

Should care plans be stored in SharePoint?

Generally no.

A care plan is the clinical record and belongs in the clinical system, which is where your clinical governance framework, audit trail and Quality Indicator reporting are anchored. Care plans drift into SharePoint when the clinical system is hard to use or slow to reach, which is a symptom rather than a solution — it creates two versions with no authoritative one.

If it is happening, the fix is usually access or performance on the clinical system side.

How do we satisfy the requirement to access information when systems are offline?

Outcome 2.7 asks for processes that make critical information available offline and allow clinical information to be recorded on paper during internet or power outages.

In practice that means each site knows which information is critical, holds a current offline copy of it, has printed forms available, and has a defined process for entering that information once systems return.

The part most often missing is the last one — providers have the paper forms but no reconciliation step, so the record has a gap.

Agency and visiting practitioners need access. How is that handled safely?

Outcome 2.7 requires access for visiting practitioners and agency workers, so excluding them is not an option.

The approach that works is time-bound, role-based access provisioned from a defined group rather than granted individually, with expiry set at the point of creation instead of relying on someone remembering to revoke it.

Manually maintained access lists in a high-turnover workforce are inaccurate within weeks, and an access list you cannot vouch for is a finding waiting to happen.

We have grown by acquisition and every site is configured differently. Where do we start?

Start with the boundary, not the technology!

Document what information exists at each site and which system is authoritative for it, because until that is agreed, standardising the platform just moves inconsistency around.

Once the boundary is set, consolidation follows a sequence that keeps care delivery undisturbed — which is what our multi-site vCIO services are structured to do.